Skip to content

Update vulnerable Rollup dependency to patch high severity #13934

Closed
@xmajox

Description

@xmajox

Is there an existing issue for this?

How do you use Sentry?

Sentry Saas (sentry.io)

Which SDK are you using?

@sentry/nextjs

SDK Version

7.119.1

Framework Version

No response

Link to Sentry event

No response

Reproduction Example/SDK Setup

Related to: GHSA-gcx4-mw62-g8wm

sentry/nextjs is currently relying on a vulnerable version of rollup 4.18.0, which has since been patched. Dependabot created the PR for it here, but the CI failed due to a minor timeout.

Would be great if you could merge this PR and backport the fix to the 7.x branch as this high severity vulnerability has been resolved for a few weeks already and is actually becoming a problem in terms of compliance.

Steps to Reproduce

Current rollup version: 4.18.0
Simply check the lockfiles

Expected Result

  • sentry/javascript has no dependency of rollup < 4.22.4
  • fix is backported to 7.x branch

Actual Result

Nothing yet...

Metadata

Metadata

Assignees

No one assigned

    Labels

    Package: nextjsIssues related to the Sentry Nextjs SDK

    Type

    Projects

    Status

    Waiting for: Product Owner

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions